Effective July 21, 2026
Security and Vulnerability Reporting
This page defines the public security boundary and reporting path for the fixed Agent Eval Kit release. It is not a security certification or a guarantee of model or customer-system performance.
Supported version
Supported version: Agent Eval Kit 1.0.0. Reports should identify this exact version and the published archive SHA-256 71580501a6004ae63e2443a5b8bac61dd84411b3dccdd5ad532f002e45e515d7. The release requires Python 3.11 or newer, uses only the Python standard library, and contains no third-party packages. The release metadata and dependency scope are recorded in the SPDX 2.3 JSON SBOM.
Security boundary
The software validates recorded local JSON evidence against a versioned contract. It does not access a network, does not collect telemetry, and does not execute customer code or arbitrary code. The caller runs tests in its own isolated environment; the software does not inspect repositories or production systems.
Reporting a vulnerability
Send a report to andudyun0504@gmail.com with the product version, archive SHA-256, Python version, operating system, affected command or input shape, reproducible steps, and a concise impact description. Include only the minimum non-sensitive material needed to reproduce the issue. Do not send passwords, production secrets, private user data, or customer source code. This reporting path does not authorize access to or testing of third-party systems or data.
Handling
Vulnerability reports are reviewed and handled on a reasonable best-effort basis. No acknowledgement, remediation, disclosure, or release deadline is promised. When a report is reproducible and within the documented product boundary, the Supplier may provide guidance, a corrected build, or an updated notice as appropriate.
Related public records: Release manifest · Terms · Privacy · Refunds